exit 1;
fi
+umask 0077
TEMP=$(mktemp -d /tmp/XXXXXX-nixops-files)
chmod go-rwx $TEMP
finish() {
rm -rf "$TEMP"
- nixops set-args --unset privateFiles
}
trap finish EXIT
for file in $files; do
pass show "Nixops/files/$file" > $TEMP/$file
done
-nixops set-args --argstr privateFiles "$TEMP"
+
+export NIX_PATH="privateFiles=$TEMP:$NIX_PATH"
+export SSH_IDENTITY_FILE="$TEMP/id_ed25519"
"$@"